Citrix NetScaler CVE-2026-19490: Gateway Auth Bypass Exploited in the Wild

By George Bailey   Published: 09/16/26   Updated: 09/16/26   3 min read

Another NetScaler week, another gateway story you cannot defer. A critical authentication bypass on Citrix NetScaler ADC and Gateway is confirmed exploited in the wild — with sensor hits starting right after a public PoC appeared.

If the appliance is configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, this is an emergency edge change.

What happened

Citrix patched CVE-2026-19490 (CVSS 9.3) on August 19, 2026. Rapid7 warned at disclosure that NetScaler deployments would draw exploit attention quickly. On September 10, CISA added the bug to KEV and set a short federal remediation clock under BOD 26-04.

Independent telemetry (Previdian / Ryan Dewhurst) reported exploitation beginning around September 3 — about a day after an exploit landed on GitHub — with matching requests from multiple countries hitting sensors. SecurityWeek summarized CISA’s warning that the flaw is being used in attacks.

Why it matters

NetScaler sits on the front door: VPN, virtual apps, and AAA. An unauthenticated bypass on that surface is how attackers skip phishing and land inside the session fabric.

History says these appliances get scanned hard within hours of a workable PoC. “We’ll take the next maintenance window” is how yesterday’s edge becomes today’s incident.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.